Senior Security Engineer
Intuit
Senior Security Engineer
Company Overview
Intuit is the global financial technology platform that powers prosperity for the people and communities we serve. With approximately 100 million customers worldwide using products such as TurboTax, Credit Karma, QuickBooks, and Mailchimp, we believe that everyone should have the opportunity to prosper. We never stop working to find new, innovative ways to make that possible.
Job Overview
Join the Adversary Management team at Intuit and take part in protecting its customers from adversaries. As a member of the Exposure Management team, you will assist in identifying and reporting exploitable risks on Intuit’s external-facing attack surface. Your contribution to this role will enable Intuit to focus its remediation efforts on the most critical and high-risk areas. Furthermore, you will help measure Intuit’s attack surface exposure to adversary threats, strategically reduce the attack surface, and partner with other Threat Intel teams to model adversary behavior.
Responsibilities
- As a core security engineer and a subject matter expert, you will identify the most risky areas of Intuit’s external-facing attack surface
- You will collaborate with other business teams to remediate specic risks that represent an imminent threat
- Research and analyze emerging threats applicable to Intuit
- Rene the risk measurement process on Intuit’s attack surface to ensure that outputs are accurate and actionable
- Partner with the Threat Intel teams to identify adversary interests and model adversary behavior
- Measure the change in Intuit’s attack surface over time to nd new and emerging areas of risk
Qualifications
- 5+ years of experience in cybersecurity
- 3+ years of offensive security related experience
- Experience with mapping attack surface and prioritizing risk
- Experience with assessing relevance and risk of publicly disclosed security vulnerabilities (like CVEs) against a company’s attack surface
- Experience with data analysis in a cybersecurity domain, specically with SQL
- Experience with coding and scripting languages (Python, Bash, Javascript)
- Cloud experience (AWS, GCP) and familiarity with containerization (Docker) a plus
- Familiarity with agile methodologies
- Bachelor’s degree in Computer Science, Software Engineering, CyberSecurity, or equivalent experience